Cyber Awareness 2023 - Learnexams (2024)

CYBER-AWARENESS-CHALLENGE-2023-UPDATE-QUESTIONS-AND-ANSWERS-100-VERIFIED-2Download

Department-of-Defense-DoD-Cyber-Awareness-Challenge-2023-1hr-Solved-100-2Download

DOD-Cyber-Awareness-2023-QUESTIONS-WITH-COMPLETE-SOLUTIONS-2Download

DOD-Cyber-Awareness-Challenge-2024-Questions-with-Accurate-Answers-2023-2Download

Answered-Cyber-Awareness-Challenge-Exam-Annual-DoD-Cyber-Awareness-Challenge-Exam-fall-2022-2023-1Download

AnsweredAnnual-DoD-Cyber-Awareness-Challenge-Exam_2022-2023-1Download

ANSWERED-DOD-CYBER-AWARENESS-2022-2023-DOD-IAA-V18.0-KNOWLEDGE-CHECK-1Download

Cyber-Awareness-2022-2023-Knowledge-Challenge-check-Graded-A-All-correct-study-guide-2Download

Cyber-Awareness-Challenge-20222023-Knowledge-Check-Question-with-complete-solutions-1Download

Cyber-Awareness-Challenge-2023-Knowledge-Check-Questions-with-complete-solution-1Download

Cyber-Awareness-Challenge-2023-Updated-with-correct-answers-1Download

Cyber-Awareness-Challenge-2023-1Download

Cyber-Awareness-Challenge-Questions-and-Answers-2023-2024-Verified-Answers-1Download

CYBER-AWARENESS-2023-KNOWLEDGE-CHECK-QUESTIONS-AND-ANSWERS-100-CORRECT-1Download

CYBER-AWARENESS-CHALLENGE-2023-INCOMPLETE-122-QUESTIONS-ANSWERS-2Download

(Spillage)
Which of the following is a good practice to prevent spillage?
Always check to make sure you are using the correct network for the level of data

(Spillage)
What does “spillage” refer to?
Information improperly moved from a higher protection level to a lower protection level

(Spillage)
Which of the following may help to prevent spillage?
Follow procedures for transferring data to and from outside agency and non-Government networks

(Spillage)
A vendor conducting a pilot program with your organization contacts you for organizational data to use in a prototype. How should you respond?
Refer the vendor to the appropriate personnel

(Spillage)
You receive an inquiry from a reporter about government information not cleared for public release. How should you respond?
Refer to reporter to your organization’s public affairs office

(Spillage)
You find information that you know to be classified on the Internet. What should you do?
Note the website’s URL and report the situation to your security point of contact

(Spillage)
You find information that you know to be classified on the Internet. What should you do?
Note the website’s URL and report the situation to your security point of contact

(Classified Data)
Who designates whether information is classification level?
Original classification authority

(Classified Data)
Which of the following must you do before using an unclassified laptop and peripherals in a collateral classified environment?
Ensure that any cameras, microphones, and Wi-Fi embedded in the laptop are physically disabled

(Classified Data)
Which of the following is a good practice to protect classified information?
Don’t assume open storage in a secure facility is authorized

(Classified Data)
What is the basis for the handling and storage of classified data?
Classification markings and handling caveats

(Insider Threat)
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague abruptly becomes hostile and unpleasant after previously enjoying positive working relationship with peers, purchases an unusually expensive new car, and has unexplained absences from work.
3 or more indicators

(Insider Threat)
Which scenario might indicate a reportable insider threat?
A colleague removes sensitive information without seeking authorization in order to perform authorized telework.

(Insider Threat)
Which of the following is a reportable insider threat activity?
Attempting to access sensitive information without need-to-know

(Insider Threat)
Which of the following is a potential insider threat indicator?
Unusual interest in classified information

(Insider Threat)
What is an insider threat?
Someone who uses authorized access, wittingly or unwittingly, to harm national security through unauthorized disclosure or other actions that may cause the loss or degradation of resources or capabilities.

(Social Networking)
How can you protect your organization on social networking sites?
Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post

(Social Networking)
Which of the following statements is true?
Adversaries exploit social networking sites to disseminate fake news.

(Social Networking)
When may you be subject to criminal, disciplinary, and/or administrative action due to online harassment, bullying, stalking, hazing, discrimination, or retaliation?
If you participate in or condone it at any time

(Controlled Unclassified Information)
Which of the following is true of Protected Health Information (PHI)?
It is created or received by a healthcare provider, health plan, or employer.

(Controlled Unclassified Information)
Which is a best practice for protecting Controlled Unclassified Information (CUI)?
Store it in a locked desk drawer after working hours

(Controlled Unclassified Information)
Which designation marks information that does not have potential to damage national security?
Unclassified

(Controlled Unclassified Information)
Which of the following is NOT an example of Personally Identifiable Information (PII)?
High school attended

(Controlled Unclassified Information)
Which of the following is true of Controlled Unclassified Information (CUI)?
CUI must be handled using safeguarding or dissemination controls.

(Controlled Unclassified Information)
Which designation includes Personally Identifiable Information (PlI) and Protected
Health Information (PHI)?
Controlled Unclassified Information (CUI)

(Controlled Unclassified Information)
Which of the following is a security best practice for protecting Personally Identifiable
Information (PII)?
Only use Government-furnished or Government-approved equipment to process
PIl.

(Physical Security)
Which of the following is a best practice for physical security?
Report suspicious activity

(Physical Security)
Which of the following best describes good physical security?
Lionel stops an individual in his secure area who is not wearing a badge.

(Identity Management)
Which of the following is true of using a DoD Public Key Infrastructure (PKI) token?
It should only be in a system while actively using it for a PKI-required task.

(Identity Management)
Which of the following is true of the Common Access Card (CAC)?
It contains certificates for identification, encryption, and digital signature.

(Identity Management)
Which of the following is an example of two-factor authentication?
A Common Access Card and Personal Identification Number

(Identity Management)
What is the best way to protect your Common Access Card (CAC) or Personal Identity
Verification (PIV) card?
Store it in a shielded sleeve

(Physical Security)
Which Cyber Protection Condition (CPCON) establishes a protection priority focus on critical functions only?
CPCON 1

(Sensitive Compartmented Information)
What must authorized personnel do before permitting another individual to enter a
Sensitive Compartmented Information Facility (SCIF)?
Confirm the individual’s need-to-know and access

(Sensitive Compartmented Information)
Which of the following is true of sharing information in a Sensitive Compartmented
Information Facility (SCIF)?
Individuals must avoid referencing derivatively classified reports classified higher than the recipient.

(Sensitive Compartmented Information)
Which of the following is true of Security Classification Guides?
The provide guidance on reasons for and duration of classification of information.

(Removable Media in a SCIF)
Which of the following is true of portable electronic devices (PEDs) in a Sensitive Compartmented Information Facility (SCIF)?
Only connect government-owned PEDs to the same level classification information system when authorized

(Removable Media in SCIF)
Which of the following is NOT a potential consequence of using removable media unsafely in a Sensitive Compartmented Information Facility (SCIF)?
Damage to the removable media

(Malicious Code)
Which of the following is a way to prevent the spread of malicious code?
Scan all external files before uploading to your computer

(Malicious Code)
Which of the following is NOT a type of malicious code?
Executables

(Website Use)
Which of the following actions ean help to protect your identity?
Shred personal documents

(Social Engineering)
What type of social engineering targets senior officials?
Whaling

(Social Engineering)
Which of the following is true?
Digitally signed e-mails are more secure.

(Social Engineering)
Which is an appropriate use of govemment e-mail?
Use a digital signature when sending attachments or hyperlinks

(Travel)
What security risk does a public Wi-Fi connection pose?
It may expose the information sent to theft.

(Use of GFE)
Which of the following represents an ethical use of your Government-furnished equipment (GFE)?
Checking personal e-mail when allowed by your organization

(Mobile Devices)
How can you protect data on your mobile computing and portable electronic devices (PEDs)?
Enable automatic screen locking after a pekod of inactivity

(Mobile Devices)
Which of the following is an example of removable media?
Flash Drive / External hard drive

(Home Computer Security)
How should you secure your home wireless network for teleworking?
Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum

SPILLAGE: Which of the following is a good practice to prevent spillage?
TBD

SPILLAGE: You receive an inquiry from a reporter about government information not cleared for public release. How should you respond?
Refer to PA

CLASSIFIED DATA: Which of the following is a good practice for telework?
use VPN

CLASSIFIED DATA: What level of damage can the unauthorized disclosure of information classified as Top Secret reasonably be expected to cause?
exceptionally grave damage

INSIDER THREAT: Which of the following is a potential insider threat indicator?
Interest in learning a foreign language (maybe)

INSIDER THREAT: What is an insider threat?
Someone who uses authorized access, wittingly or unwittingly, to harm…… (maybe)

**Insider Threat
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague saves money for an overseas vacation every year, is a single father, and occasionally consumes alcohol.
1 (maybe)

SOCIAL NETWORKING: Which of the following is a security best practice when using social networking sites?
Avoiding posting your mother’s maiden name

SOCIAL NETWORKING: Which of the following statements is true?
Adversaries exploit social networking sites to disseminate fake news.

SOCIAL NETWORKING: Which of the following statements is true?
Many apps and smart devices collect and share your personal information and contribute to your online identity

CUI: Which of the following best describes a way to safely transmit Controlled Unclassified Information (CUI)?
TBD

CUI: Which of the following is true of Protected Health Information (PHI)?
TBD

CUI: Which designation includes PII and PHI?
Sensitive information

PHYSICAL SECURITY: Which of the following best describes good physical security?
Lionel stops an individual in his secure area who is not wearing a badge

IDENTITY MANAGEMENT: Which of the following is true of the CAC or PIV card?
You should remove and take your CAC/PIV card whenever you leave your workstation

IDENTITY MANAGEMENT: Which of the following is true of using a DoD PKI token?
It should only be in a system while actively using it for a PKI-required task

SENSITIVE COMPARTMENTED INFORMATION: Which of the following is true of transmitting sensitive compartmented information (SCI)?
You many only transport SCI if you have been courier-briefed for SCI.

SENSITIVE COMPARTMENTED INFORMATION: Which of the following is true of Sensitive Compartmented Information (SCI)?
Access requires Top Secret clearance and indoctrination into the SCI program.

REMOVABLE MEDIA IN A SCIF: Which of the following is true of portable electronic devices (PEDs) in a Sensitive Compartmented Information Facility (SCIF)?
All personal and government-owned PEDs are prohibited in a SCIF (NOPE), only authorized govt PEDS (??)

MALICIOUS CODE: Which of the following is NOT a type of malicious code?
Executables

WEBSITE USE: Which of the following actions can help to protect your identity?
Shred personal documents

SOCIAL ENGINEERING: What action should you take with a compressed Uniform Resource Locator (URL) on a website known to you?
investigate the destination by using the preview feature to see where the link goes

SOCIAL ENGINEERING: How can you protect yourself from social engineering?
Verify the identity of all individuals.

SOCIAL ENGINEERING: what is a common indicator of a phishing attempt?
a claim that you must update or validate information

TRAVEL: What security risk does a public Wi-Fi connection pose?
It may prohibit the use of a VPN (NOPE), It may expose the information sent to theft (??),

USE OF GFE: Which of the following is NOT a permitted way to connect a personally-owned monitor to your GFE?
USB

MOBILE DEVICES: Which of the following best describes the conditions under which mobile devices and applications can track your location?
It may occur at any time without your knowledge or consent.

MOBILE DEVICES: How can you protect data on your mobile computing and portable electronic devices (PEDs)?
Enable automatic screen locking after a period of inactivity.

SPILLAGE: You find information that you know to be classified on the Internet. What should you do?
Note the website’s URL and report the situation to your security point of contact

HOME COMPUTER SECURITY: How should you secure your home wireless network for teleworking?
Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum.

SPILLAGE: Which of the following may help to prevent spillage?
Follow procedures for transferring data to and from outside agency and non-government networks.

CLASSIFIED DATA: Who designates whether information is classified and its classification level?
Original classification authority (??)

Which of the following may help to prevent spillage?
Follow procedures for transferring data to and from outside agency and non-Government networks

A vendor conducting a pilot program… how should you respond?
Refer the vendor to the appropriate personnel

What level of damage… Top Secret be expected to cause?
Exceptionally grave

Which of the following is a good practice for telework?
Position your monitor so it is not facing others

Inquiry from a reporter…?
Refer to public affairs

What does spillage refer to?
Information improperly moved from higher to lower protection level

Which of the following is a good practice to protect classified information?
Don’t assume open storage is authorized

Which scenario might indicate a reportable insider threat?
A colleague removes sensitive information without seeking authorization

Which of the following is a reportable insider threat activity?
Attempting to access sensitive information without need to know

What function do Insider Threat Programs aim to fulfill?
Proactively identify potential threats and formulate yadayadayada

How can you protect your organization on social networking sites?
Ensure there are no identifiable landmarks visible in photos

What piece of information is safest to include on your social media profile?
If you don’t know the answer to this one, please do the training in full. you’re dumb forreal.

Which of the following is a security best practice when using social networking sites?
Avoiding posting your mother’s maiden name

Which of the following statements is true?
Many apps and smart devices collect and share your personal information and contribute…..

Which of the following statements is true?
Adversaries exploit social networking sites to disseminate fake news.

A trusted friend in your social network posts vaccine information on a website unknown to you. What action should you take?
some of yall mfs need to read this twice- RESEARCH THE SOURCE TO EVALUATE ITS CREDIBILITY AND RELIABILITY

Which of the following best describes a way to safely transmit CUI
Debra ensures all recipients have requires clearance and need to know before sending via encrypted email

Which of the following is true of PHI?
It is created of received by a healthcare provider, health plan, or employer

What designation includes PII and PHI?
CUI

Which is a best practice for protecting CUI?
Store in locked drawer after working hours

Which of the following is true of CUI?
CUI must be handled using safeguarding or dissemination controls

Which of the following is NOT PII?
High school attended

Which of the following describes good physical security
Lionel stops an individual in his secure area who’s not wearing a badge

Which Cyber Protection Condition establishes protection priority focus on critical functions only?
CPCON 1

Which of the following is an example of a strong password?
password12345, dummy.

Which of the following is true of using a DoD PKI token?
It should only be in a system when actively using it for a PKI-required task.

Which of the following is true of the CAC or PIV card
You should remove and take your CAC/PIV when you leave your station.

Which of the following is an example of two-factor authentication?
CAC and PIN

Which of the following is true of sharing information in a SCIF?
Individuals must avoid referencing derivatively ……

A compromise of SCI occurs when a person who doesn’t have required clearance or access caveats comes into possession of SCI
in any manner

Which of the following is true of transmitting SCI?
You may only transport SCI if you have been courier briefed for SCI

Which of the following is NOT a potential consequence of using removable media unsafely in a SCIF?
Damage to the removable media

How should you label removable media used in a SCIF?
With the maximum classification, date of creation, POC, and CM Control Number

Which of the following is true of downloading apps?
For Government-owned devices, use approved and authorized applications only

Which of the following statements is true of cookies?
You should confirm that a site that wants to store a cookie uses an encrypted link

How should you respond to the theft of your identity?
THE ANSWER IS NOT notify your security POC.

“to respond to identity theft if it occurs: contact credit reporting agencies, contact financial institutions to cancel accounts, monitor credit card statements for unauthorized purchases, report the crime to local law enforcement”

Which of the following is true of internet hoaxes?
They can be part of a DDoS attack.

How can you protect yourself from social engineering?
Verify the identity of all individuals.

What type of social engineering targets senior officials?
Whaling

Which of the following is true?
Digitally signed emails are more secure.

What action should you take with a compressed URL on a website known to you?
Search for instructions on how to preview where the link actually leads

Which of the following is a concern when using your Government issued laptop in public?
The physical security of the device

What security risk does a public Wi-Fi connection pose?
It may expose the information sent to theft

Which of the following is NOT a permitted way to connect a personally-owned monitor to your GFE?
USB

Which of the following is a best practice for using removable media?
Avoid inserting removable media with unknown content into your computer

Which of the following is NOT a risk associated with NFC?
Additional data charges

How can you protect data on your mobile computing and portable electronic devices (PEDs)
Enable automatic screen locking after a period of inactivity

Which of the following best describes the conditions under which mobile devices and apps can track your location?
It may occur at any time without your knowledge or consent.

Which of the following is true of Internet of Things (IoT) devices?
They can become an attack vector to other devices on your home network

How should you secure your home wireless network for teleworking?
Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum

A vendor conducting a pilot program with your organization contacts you for organizational data to use in a prototype. How should you respond?
Refer the vendor to the appropriate personnel.

When classified data is not in use, how can you protect it?
Store classified data appropriately in a GSA-approved vault/container.

What is the basis for handling and storage of classified data?
Classification markings and handling caveats.

Which of the following must you do before using an unclassified laptop and peripherals in a collateral classified environment?
Ensure that any cameras, microphones, and Wi-Fi embedded in the laptop are physically disabled.

What level of damage to national security can you reasonably expect Top secret information to cause if disclosed?
Exceptionally grave damage.

Which of the following is true about telework?
You must have your organization’s permission to telework.

Which of the following is true of protecting classified data?
Classified material must be appropriately marked.

Which of the following is a reportable insider threat activity?
Attempting to access sensitive information without need-to-know.

Which scenario might indicate a reportable insider threat?
a colleague removes sensitive information without seeking authorization in order to perform authorized telework.

Which of the following is a potential insider threat indicator?
1) Unusual interest in classified information. 2) Difficult life circ*mstances, such as death of spouse.

Which piece of information is safest to include on your social media profile?
Your favorite movie.

Which of the following statements is true?
Many apps and smart devices collect and share your personal information and contribute to your online identity.

How can you protect your organization on social networking sites?
Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post.

Which is a best practice for protecting Controlled Unclassified Information (CUI)?
Store it in a locked desk drawer after working hours.

Which of the following best describes a way to safely transmit Controlled Unclassified Information (CUI)?
Paul verifies that the information is CUI, includes a CUI marking in the subject header, and digitally signs an e-mail containing CUI.

Which designation includes Personally Identifiable Information (PII) and Protected Health Information (PHI)?
Controlled Unclassified Information (CUI)

Which of the following is NOT an example of CUI?
Press release data.

Which of the following is NOT a correct way to protect CUI?
CUI may be stored on any password-protected system.

Which of the following best describes good physical security?
Lionel stops an individual in his secure area who is not wearing a badge.

Which of the following is an example of two-factor authentication?
A Common Access Card and Personal Identification Number.

What is the best way to protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?
Store it in a shielded sleeve.

What must authorized personnel do before permitting another individual to enter a Sensitive Compartmented Information Facility (SCIF)?
Confirm the individual’s need-to-know and access.

Which of the following is true of Sensitive Compartmented Information (SCI)?
Access requires Top Secret clearance and indoctrination into the SCI program.

Which of the following is NOT a potential consequence of using removable media unsafely in a Sensitive Compartmented Information Facility (SCIF)?
Damage to the removable media.

What portable electronic devices (PEDs) are permitted in a SCIF?
Only expressly authorized government-owned PEDs.

What is the response to an incident such as opening an uncontrolled DVD on a computer in a SCIF?
All of these.

Which of the following is NOT a type of malicious code?
Executables.

Which of the following actions can help tp protect your identity?
Shred personal documents.

Which is an appropriate use of government e-mail?
Use a digital signature when sending attachments or hyperlinks.

What type of social engineering targets particular groups of people?
Spear phishing.

How can you protect yourself from social engineering?
Verify the identity of all individuals.

Which of the following is true of traveling overseas with a mobile phone?
A personally owned device approved under Bring Your Own Approved Device (BYOAD) policy must be unenrolled while out of the country.

What should Sara do when using publicly available Internet, such as hotel Wi-Fi?
Only connect with Government VPN.

What is the danger of using public Wi-Fi connections?
Both of these.

Which of the following personally-owned computer peripherals is permitted for use with Government-furnished equipment?
A headset with a microphone through a Universal Serial Bus (USB) port.

How can you protect data on your mobile computing and portable electronic devices (PEDs)?
Enable automatic screen locking after a period of inactivity.

Which of the following is an example of removable media?
External hard drive.

Which of the following is true of Internet of Things (IoT) devices?
They can become an attack vector to other devices on your home network.

When is it appropriate to have your security badge visible?
At all times when in the facility.

What should the owner of this printed SCI do differently?
Retrieve classified documents promptly from printers.

What should the participants in this conversation involving SCI do differently?
Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed.

Which of the following demonstrates proper protection of mobile devices?
Linda encrypts all of the sensitive data on her government-issued mobile devices.

Which of the following does NOT constitute spillage?
Classified information that should be unclassified and is downgraded.

Which of the following is NOT an appropriate way to protect against inadvertent spillage?
Use the classified network for all work, including unclassified work.

Which of the following should you NOT do if you find classified information on the internet?
Download the information.

Who designates whether information is classified and its classification level?

Which of the following is a good practice to protect classified information?

Which of the following may help to prevent spillage?
Follow procedures for transferring data to and from outside agency and non-government networks.

Who designates whether information is classified and its classification level?
Original classification authority.

In addition to avoiding the temptation of greed to betray his country, what should Alex do differently?
Avoid talking about work outside of the workplace or with people without a need-to-know.

How many insider threat indicators does Alex demonstrate?
Three or more.

What should Alex’s colleagues do?
Report the suspicious behave in accordance with their organization’s threat policy.

Which of the following is true?
Digitally signed e-mails are more secure.

Which of the following best describes the conditions under which mobile devices and applications can track your location?
It is often the default but can be prevented by disabling the location function.

When is it okay to charge a personal mobile device using government-furnished equipment (GFE)?
This is never okay.

Which of the following demonstrates proper protection of mobile devices?
Linda encrypts all of the sensitive data on her government-issued mobile devices.

What security risk does a public Wi-Fi connection pose?
It may prohibit the use of a virtual private network (VPN).

Which of the following represents an ethical use of your Government-furnished equipment (GFE)?
Checking personal e-mail when allowed by your organization.

When may you be subject to criminal, disciplinary, and/or administrative action due to online harassment, bullying, stalking, hazing, discrimination, or retaliation?
If you participate in or condone it at any time.

How can you protect yourself on social networking sites?
Validate friend requests through another source through another source before confirming them.

Which piece of information is safest to include on your social media profile?
Photos of your pet.

Which of the following is true of removable media and portable electronic devices (PEDs)?
They have similar features, and the same rules and protections apply to both.

Which of the following is a security best practice for protecting Personally Identifiable Information (PII)?
Only use Government-approved equipment to process PII.

Which of the following is true of Controlled Unclassified Information (CUI)?
CUI must be handled using safeguarding or dissemination controls.

Which Cyber Protection Condition (CPCON) establishes a protection priority focus on critical functions only?
CPCON 1.

Which of the following is true of the Common Access Card (CAC) or Personal Identity Verification (PIV) card?
You should remove and take your CAC/PIV card whenever you leave your workstation.

Which of the following is an example of a strong password?
%2ZN=Ugq

A compromise of Sensitive Compartmented Information (SCI) occurs when a person who does not have the required clearance or access caveats comes into possession of SCI________.
in any manner.

Which of the following is a good practice to protest classified information?
Don’t assume open storage in a secure facility is authorized.

Based on the description that follows, how many potential insider threat indicators(s) are displayed? A colleague saves money for an overseas vacation every year, is a single father, and occasionally consumes alcohol.
2 indicators.

Which of the following statements is true?
Adversaries exploit social networking sites to disseminate fake news.

Which of the following is true about URLs?
May be used to mask malicious intent.

What does “spillage refer to?
Information improperly moved from a higher protection level to a lower protection level.

Based on the description that follows, haw many potential insider threat indicator(s) are displayed? a colleague enjoys playing videos games, regularly uses social media, and frequently forgets to secure her smartphone elsewhere before entering areas where it is prohibited.
1 indicator

A trusted friend in your social network posts a link to vaccine information on a website unknown to you. What action should you take?
Research the source to evaluate its credibility and reliability.

Which of the following is true of the Common Access Card (CAC)?
It contains certificates for identification, encryption, and digital signature.

Which of the following is true of portable electronic devices (PEDs) in a Sensitive Compartmented Information Facility (SCIF)?
only connect government-owned PEDs to the same level classification information system when authorized.

Which of the following is true of downloading apps?
For Government-owned devices, use approved and authorized applications only.

Which of the following statements is true of cookies?
You should confirm that a site that wants to store a cookie uses an encrypted link.

What action should you take with a compressed Uniform Resource Locator (URL) on a website known to you?
Search for instructions on how to preview where the link actually leads.

Which of the following is a best practice for using removable media?
Avoid inserting removable media with unknown content into your computer.

How should you secure your home wireless network for teleworking?
Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum.

(Spillage) What should you do if a reporter asks you about potentially classified information on the web?

Refer the reporter to your organization’s public affairs office.

What does “spillage” refer to?

Information improperly moved from a higher protection level to a lower protection level

(Spillage) Which of the following is a good practice to aid in preventing spillage?

Be aware of classification markings and all handling caveats.

(Spillage) After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know this project is classified. What should be your response?

Attempt to change the subject to something non-work related, but neither confirm nor deny the article’s authenticity.

(Spillage) What should you do when you are working on an unclassified system and receive an email with a classified attachment?

Call your security point of contact immediately.

(Spillage) What is required for an individual to access classified data?

Appropriate clearance; signed and approved non-disclosure agreement; and need-to-know.

(Spillage) When classified data is not in use, how can you protect it?

Store classified data appropriately in a GSA-approved vault/container.

(Insider Threat) A colleague vacations at the beach every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?

0 indicators

(Insider Threat) Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.

1 indicators

(Spillage) What type of activity or behavior should be reported as a potential insider threat?

Coworker making consistent statements indicative of hostility or anger toward the United States and its policies.

(Spillage) What advantages do “insider threats” have over others that allows them to cause damage to their organizations more easily?

Insiders are given a level of trust and have authorized access to Government information systems.

(Spillage) Which of the following is a best practice to protect information about you and your organization on social networking sites and applications?

Use only personal contact information when establishing personal social networking accounts, never use Government contact information.

(Spillage) When is the safest time to post details of your vacation activities on your social networking website?

When your vacation is over, after you have returned home

(social networking) When is the safest time to post details of your vacation activities on your social networking profile?

After you have returned home following the vacation

(Spillage) What level of damage can the unauthorized disclosure of information classified as confidential reasonably be expected to cause?

Damage to national security

(Spillage) Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?

Secret

(Spillage) Which of the following practices may reduce your appeal as a target for adversaries seeking to exploit your insider status?

Remove your security badge after leaving your controlled area or office building.

(Sensitive Information) What type of unclassified material should always be marked with a special handling caveat?

For Official Use Only (FOUO)

(Sensitive Information) Which of the following is NOT an example of sensitive information?

Press release data

(Sensitive Information) Which of the following is true about unclassified data?

When unclassified data is aggregated, its classification level may rise.

(Sensitive Information) Which of the following represents a good physical security practice?

Use your own security badge, key code, or Common Access Card (CAC)/Personal Identity Verification (PIV) card.

(Sensitive Information) What certificates are contained on the Common Access Card (CAC)?

Identification, encryption, and digital signature

(Sensitive Information) What should you do if a commercial entity, such as a hotel reception desk, asks to make a photocopy of your Common Access Card (CAC) for proof of Federal Government employment?

Do not allow your CAC to be photocopied.

(Sensitive Compartmented Information) What describes how Sensitive Compartmented Information is marked?

Approved Security Classification Guide (SCG)

(Sensitive Compartmented Information) Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?

A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.

(Sensitive Compartmented Information) What portable electronic devices (PEDs) are allow in a Secure Compartmented Information Facility (SCIF)?

Government-owned PEDs, if expressly authorized by your agency.

(Malicious Code) What are some examples of malicious code?

Viruses, Trojan horses, or worms

(Malicious Code) Which of the following is NOT a way that malicious code spreads?

Legitimate software updates

(Malicious Code) While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?

Since the URL does not start with “https,” do not provide your credit card information.

(Malicious Code) Which email attachments are generally SAFE to open?

Attachments contained in a digitally signed email from someone known

(Malicious Code) What is a common indicator of a phishing attempt?

It includes a threat of dire circ*mstances.

(Malicious Code) Which of the following is true of Internet hoaxes?

They can be part of a distributed denial-of-service (DDoS) attack.

(Malicious Code) Upon connecting your Government-issued laptop to a public wireless connection, what should you immediately do?

Connect to the Government Virtual Private Network (VPN).

(Malicious Code) A coworker has asked if you want to download a programmer’s game to play at work. What should be your response?

I’ll pass

(Malicious Code) What are some examples of removable media?

Memory sticks, flash drives, or external hard drives

(Malicious Code) Which are examples of portable electronic devices (PEDs)?

laptops, fitness bands, tablets, smartphones, electric readers, and Bluetooth devices

(Malicious Code) What is a good practice to protect data on your home wireless systems?

Ensure that the wireless security features are properly configured.

(social networking) When may you be subjected to criminal, disciplinary, and/or administrative action due to online misconduct?

If you participate in or condone it at any time

(social networking) Which of the following is a security best practice when using social networking sites?

Use only personal contact information when establishing your personal account

(controlled unclassified information) Which of the following is NOT an example of CUI?

press release data

(controlled unclassified information) Which of the following is NOT correct way to protect CUI?

CUI may be stored on any password-protected system.

(Physical Security) which Cyberspace Protection Condition (CPCON) establishes a protection priority focus on critical and essential functions only?

(Answer) CPCON 2 (High: Critical and Essential Functions)

CPCON 1 (Very High: Critical Functions)
CPCON 3 (Medium: Critical, Essential, and Support Functions)
CPCON 4 (Low: All Functions)
CPCON 5 (Very Low: All Functions)

(Identity Management) What certificates are contained on the Common Access Card (CAC)?

Identification, encryption, and digital signature

(Identity Management) Which of the following is an example of two-factor authentication?

Your password and the second commonly includes a text with a code sent to your phone

(Sensitive Information) What guidance is available from marking Sensitive Information information (SCI)?

Security Classification Guide (SCG)

(Sensitive Information) What must the dissemination of information regarding intelligence sources, methods, or activities follow?

The Director of National Intelligence.

(removable media) If an incident occurs involving removable media in a Sensitive Compartmented Information Facility (SCIF), what action should you take?

Notify your security point of contact

Which of the following actions can help to protect your identity?

What is whaling?

Looking at your MOTHER, and screaming “THERE SHE BLOWS!!”
(A type of phishing targeted at senior officials)
Which is still your FAT A$$ MOTHER!

Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?

Do not access website links, buttons, or graphics in e-mail

What type of social engineering targets particular individuals, groups of people, or organizations?

Spear phishing

(Travel) Which of the following is a concern when using your Government-issued laptop in public?

Others may be able to view your screen.

(GFE) When can you check personal e-mail on your Government-furnished equipment (GFE)?

If allowed by organizational policy

(Mobile Devices) Which of the following statements is true?

Mobile devices and applications can track your location without your knowledge or consent.

(Mobile Devices) When can you use removable media on a Government system?

When operationally necessary, owned by your organization, and approved by the appropriate authority

(Home computer) Which of the following is best practice for securing your home computer?

Create separate accounts for each user

*Spillage
Which of the following does NOT constitute spillage?
-Classified information that should be unclassified and is downgraded.

Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague saves money for an overseas vacation every year, is a single father, and occasionally consumes alcohol.

0 indicators

Which of the following is a potential insider threat indicator?

Unusual interest in classified information

Which of the following is a reportable insider threat activity?

Attempting to access sensitive information without a need-to-know

Which of the following is NOT an appropriate way to protect against inadvertent spillage?
-Use the classified network for all work, including unclassified work.

Which of the following should you NOT do if you find classified information on the internet?
-Download the information.

*Classified Data
Which of the following individuals can access classified data?
-Darryl is managing a project that requires access to classified information. He has the appropriate clearance and a signed approved non-disclosure agreement.

Which of the following is a god practice to protect classified information?
-Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.

*Insider Threat
What threat do insiders with authorized access to information or information systems pose?
-They may wittingly or unwittingly use their authorized access to perform actions that result in the loss or degradation of resources or capabilities.

Which type of behavior should you report as a potential threat?
-Hostility or anger toward the United States and its policies.

Which of the following practices may reduce your appeal as a target for adversaries seeking to exploit you insider status?
-Remove your security badge after leaving your controlled area or office building.

*Social Networking

Your cousin posted a link to an article with an incendiary headline on social media. What action should you take?
-Research the source of the article to evaluate its credibility and reliability.

Which of the following is a security best practice when using social networking sites?
-Turn off Global Positioning System (GPS) before posting pictures of yourself in uniform with identifiable landmarks.

How should you respond to the theft of your identity?
-Notify law enforcement.

*Malicious Code
What is a possible effect of malicious code?
-Files may be corrupted, erased, or compromised.

*Social Engineering
What action should you take with an e-mail from a friend containing a compressed Uniform Resource Locator (URL)?
-Investigate the link’s actual destination using the preview feature.

How can you protect yourself from internet hoaxes?
-Use online sites to confirm or expose potential hoaxes.

How can you protect yourself from social engineering?
-Follow instructions given only by verified personnel.

*Travel
What security risk does a public Wi-Fi connection pose?
-It may expose the connected device to malware.

*Use of GFE
When can you check personal e-mail on your Government-furnished equipment (GFE)?
-If allowed by organizational policy.

*Mobile Devices
What can help to protect data on your personal mobile device?
-Secure it to the same level as Government-issued systems.

Which of the following is an example of near field communication (NFC)?
-A smartphone that transmits credit card payment information when held in proximity to a credit card reader.

*Home Computer Security
Which of the following is a best practice for securing your home computer?
-Create separate accounts for each user.

Cyber Awareness 2023 - Learnexams (2024)
Top Articles
Latest Posts
Article information

Author: Chrissy Homenick

Last Updated:

Views: 6607

Rating: 4.3 / 5 (74 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Chrissy Homenick

Birthday: 2001-10-22

Address: 611 Kuhn Oval, Feltonbury, NY 02783-3818

Phone: +96619177651654

Job: Mining Representative

Hobby: amateur radio, Sculling, Knife making, Gardening, Watching movies, Gunsmithing, Video gaming

Introduction: My name is Chrissy Homenick, I am a tender, funny, determined, tender, glorious, fancy, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.